Guard Core Go: the API security core engine for Go. A framework-agnostic port of the [guard-core](https://github.com/Guard-Core/guard-core) detection engine that powers the Go adapters: [nethttp-guard](https://github.com/Guard-Core/nethttp-guard), [gin-guard](https://github.com/Guard-Core/gin-guard), [echo-guard](https://github.com/Guard-Core/echo-guard), and [fiber-guard](https://github.com/Guard-Core/fiber-guard).
Website · Docs · Playground · Dashboard · Discord
Guard Core is the Python engine. Framework adapters are thin wrappers that translate native request/response types into Guard Core's protocols. The telemetry agents ship security events and metrics to the monitoring backend. Parallel engine implementations exist for Go, PHP, TypeScript (on npm), and Rust (on crates.io) - all ports of the same reference semantics, conformance-tested against the shared adversarial corpus.
| Package | Role | PyPI |
|---|---|---|
| guard-core | Framework-agnostic security engine | |
| guard-agent | Telemetry agent | |
| fastapi-guard | FastAPI / Starlette adapter | |
| flaskapi-guard | Flask adapter | |
| djapi-guard | Django adapter | |
| tornadoapi-guard | Tornado adapter |
Go modules published via GitHub releases. Production-ready.
| Package | Role | Release |
|---|---|---|
| guard-core-go | Go engine | |
| nethttp-guard | net/http adapter | |
| gin-guard | Gin adapter | |
| echo-guard | Echo (v4) adapter | |
| fiber-guard | Fiber (v3) adapter | |
| guard-agent-go | Telemetry agent |
Published on Packagist under the rennf93 vendor. Production-ready.
| Package | Role | Packagist |
|---|---|---|
| guard-core-php | PHP engine | |
| laravel-guard | Laravel adapter | |
| symfony-guard | Symfony adapter | |
| psr15-guard | PSR-15 adapter | |
| slim-guard | Slim 4 adapter | |
| guard-agent-php | Telemetry agent |
Published under the @guardcore npm scope; source in the guard-core-ts monorepo. Production-ready.
| Package | Role | npm |
|---|---|---|
| @guardcore/core | Core engine | |
| @guardcore/express | Express adapter | |
| @guardcore/nestjs | NestJS adapter | |
| @guardcore/fastify | Fastify adapter | |
| @guardcore/hono | Hono (edge) adapter | |
| guardagent | Telemetry agent |
Published on crates.io. Production-ready.
| Package | Role | crates.io |
|---|---|---|
| guard-core-engine | Core engine crate | |
| guard-core-rs | Facade crate (consumer entry point) | |
| actix-guard-rs | Actix Web adapter | |
| axum-guard-rs | Axum adapter | |
| tower-guard-rs | Tower adapter | |
| rocket-guard-rs | Rocket adapter | |
| guard-agent-rs | Telemetry agent |
| Package | Role | PyPI |
|---|---|---|
| guard-core-mcp | MCP server: config validation, docs search, detection sandbox |
- Penetration attempt detection: XSS, SQLi, command injection, path traversal, SSRF, NoSQL, template injection, deserialization, and more, with Python-engine-compatible semantics
- IP banning: threshold-based auto-banning with per-threat-category tuning
- Distributed rate limiting: Redis-backed atomic Lua scripts with endpoint-level overrides
- Cloud provider IP blocking: AWS, GCP, Azure, DigitalOcean, Linode, Vultr ranges
- Route-scoped configuration: per-route rate limits, auth requirements, header requirements, custom validators
- Redis state with fail-open / fail-secure modes: shared bans and counters across instances
- OnBlock telemetry hook: the agent wiring seam for every blocked or passive verdict
📚 Documentation - full technical documentation for this package.
🛡️ Guard Core - the engine's reference documentation.
🤖 Monitoring Agent Integration - monitor your Guard instance with a monitoring agent.
go get github.com/rennf93/guard-core-go/v4@v4.0.4The module is github.com/rennf93/guard-core-go/v4; the primary package is guardcore.
package main
import (
"log"
guardcore "github.com/rennf93/guard-core-go/v4/guardcore"
)
func main() {
cfg := guardcore.DefaultSecurityConfig()
engine, err := guardcore.NewEngine(cfg)
if err != nil {
log.Fatal(err)
}
if err := engine.Initialize(); err != nil {
log.Fatal(err)
}
}The engine provides IP control and rate limiting, signature-based penetration detection, security headers, behavioral tracking, and cloud-provider range checks. Framework adapters translate native request types into the guardcore request surface and verdicts back into exact HTTP responses; build your own integration against the engine directly when an adapter is not available.
MIT. See LICENSE.